Skip to content

fix(install): resolve every tool version at install time, and upgrade on re-run - #81

Merged
catinspace-au merged 2 commits into
mainfrom
fix/latest-at-install-time
Sep 2, 2026
Merged

catinspace-au merged 2 commits into
mainfrom
fix/latest-at-install-time

Conversation

@catinspace-au

Copy link
Copy Markdown
Contributor

A version written into this repo is current the day someone types it and stale every day after. Go was pinned at 1.26.7 while upstream was on 1.27.1 - which is also why hyperi-ci had to bump golangci-lint, since a linter behind the toolchain cannot read the newer stdlib.

Worth saying up front: --pinned was never the thing biting. It defaults off, so a normal install already resolved latest for all twelve tools in hyperi_versions. The pins that bound on every install were go, rustup, fnm, openbao and flarectl.

Gone entirely: hyperi_versions, hyperi_pinned, install.sh --pinned, and tools/check_version_pins.py with its tests. Every task already had an else latest branch, so deleting the map changed no default - it removed the only path that installed something older. The drift check existed to keep a hand-copied mirror of hyperi-ci honest, and the mirror is what went. That check was also failing on every PR to this repo, including #77, for a bump nobody here made.

Resolved at install time instead:

  • go - go.dev/dl/?mode=json gives the current stable plus a SHA256 per file, so the download stays verified. hyperi-update already used this exact endpoint, so the role was the outlier, not the script.
  • rustup - the current rustup-init and the .sha256 published beside it.
  • fnm, openbao, flarectl - /releases/latest, or @latest for flarectl.

Re-running a role now upgrades instead of skipping, which the creates: guards used to prevent:

  • cargo install-update --all --locked, gated on --list reporting something outdated so a current box pays one registry poll rather than a rebuild sweep. Rust already had the tooling for this - the role installs cargo-update and the comments called it the refresh path, it was just never wired in.
  • rustup update stable, gated on rustup check.
  • flarectl drops its creates: guard, since go install re-links regardless.

Kept on purpose: node_major picks an LTS line rather than a release, and NodeSource's signed repo patches it in place. Rust needs no equivalent - edition 2024 comes with whatever stable rustup installs.

flarectl is the one place latest trades away a real guard: it sits on cloudflare-go's v0 branch, which makes no semver promise. Taken deliberately - it is a CLI, and a stale one is the worse failure.

Two bugs surfaced on the way and are fixed here. Unpacking Go had no not ansible_check_mode guard, invisible while the pin matched what was installed. And both new version checks carry failed_when: false, so a broken toolchain returned empty output and the upgrade skipped as if current - unmeasurable is not the same as up to date, so a failed check now falls through to attempting the upgrade.

Verified on desktop-derek, a real converge rather than check mode: Go went 1.26.0 to go1.27.1, and golangci-lint installed 2.13.2 - newer than even hyperi-ci's v2.13.1 pin. run-tests.sh green with 42 tests, and full-repo ansible-lint drops from 307 findings to 304 (measured against main in a worktree), so this adds none.

… on re-run

A version written into this repo is current on the day someone types it and
stale every day after. Go was pinned to 1.26.7 while upstream was on 1.27.1,
which is also why hyperi-ci had to bump golangci-lint -- a linter behind the
toolchain cannot read the newer stdlib.

The `--pinned` flag was never the thing biting: it defaults off, so a normal
install already resolved latest for all twelve tools in `hyperi_versions`. What
bound on every install was `go`, `rustup`, `fnm`, `openbao` and `flarectl`.

Removed outright:

- `hyperi_versions`, `hyperi_pinned`, `install.sh --pinned`, and
  `tools/check_version_pins.py` with its tests. Every task already carried an
  `else latest` branch, so deleting the map changed no default -- it removed the
  only path that installed something older. The drift check existed to keep a
  hand-copied mirror of hyperi-ci honest, and the mirror is what went.

Resolved at install time instead:

- go: `go.dev/dl/?mode=json` gives the current stable and a SHA256 per file, so
  the download stays verified. hyperi-update already used this endpoint.
- rustup: the current `rustup-init` plus the `.sha256` published beside it.
- fnm, openbao, flarectl: `/releases/latest`, or `@latest` for flarectl.

Re-running a role now upgrades rather than skipping:

- `cargo install-update --all --locked`, gated on `--list` reporting something
  outdated so a current box pays one registry poll instead of a rebuild sweep.
- `rustup update stable`, gated on `rustup check`.
- flarectl loses its `creates:` guard, since `go install` re-links regardless.

Kept deliberately: `node_major` selects an LTS line rather than a release, and
NodeSource's signed repo patches it in place. Rust needs no equivalent -- edition
2024 comes with whatever stable rustup installs.

Also fixes a check-mode gap the live resolution exposed: unpacking Go had no
`not ansible_check_mode` guard, which never showed while the pin matched what
was already installed.

run-tests.sh green, 42 tests. Full-repo ansible-lint goes 307 findings to 304.
…f failed

`rustup check` and `cargo install-update --list` both carry failed_when: false,
so a broken toolchain returned empty output and the update tasks skipped as if
everything were current. Unmeasurable is not the same as up to date.

Found on desktop-derek, where ~/.rustup is a dangling symlink to a /cache
volume that was rebuilt without it, so every rustup call exits non-zero.
@catinspace-au
catinspace-au merged commit ce9950f into main Sep 2, 2026
16 checks passed
@catinspace-au
catinspace-au deleted the fix/latest-at-install-time branch September 2, 2026 23:27
@github-actions

github-actions Bot commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant